BigCommerce Supply-Chain Breach Exposes Customer Data via Third-Party App

A cyberattack on BigCommerce through compromised Ribon app credentials exposed customer information like names and emails, raising phishing risks for affected users.

BigCommerce Supply-Chain Breach Exposes Customer Data via Third-Party App
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

How Did the BigCommerce Data Breach Occur?

The recent cyber incident targeting BigCommerce was a software supply-chain attack, where attackers compromised credentials belonging to a third-party ecommerce app called Ribon. This app, integrated by many merchants to enhance store functionalities, had its access keys stolen. Using those credentials, the attackers inserted malicious scripts into some merchant storefronts, allowing them to access and extract customer data stored on BigCommerce systems.

The breach lasted from September 13 to September 17, 2026, after which BigCommerce revoked the compromised credentials and removed the app from affected stores to stop further intrusion. Although the company described the affected merchants as a "small number," reports indicate Ribon was installed on hundreds of stores, suggesting a broader impact.

What Customer Data Was Exposed and What Was Not?

BigCommerce Removes Ribon Apps After Storefront Script Injection
BigCommerce Removes Ribon Apps After Storefront Script Injection

Customers of impacted merchants, including online retailer Master of Malt, had their personally identifiable information (PII) accessed in the attack. Data exposed includes names, email addresses, phone numbers, and physical mailing addresses. Importantly, sensitive payment data such as passwords, credit card details, and other payment information remained secure as these are stored separately and were not compromised.

These details can be sufficient for attackers to launch phishing scams, impersonation attempts, or targeted marketing frauds against affected customers.

Who Should Be Concerned and What Are the Risks?

Merchants using BigCommerce who installed Ribon or Ribon 1.5 apps during the attack window are likely impacted, along with their customers. Even businesses not directly targeted may indirectly face repercussions if their store was affected. The exposure of contact information increases the chance of phishing emails or scam calls pretending to be from the store or BigCommerce.

Law firms have already started advising customers on potential claims, emphasizing the importance of vigilance regarding suspicious communications.

What Can Impacted Users Do to Protect Themselves?

Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer  Data
Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data

Since payment credentials were not accessed, immediate financial risk is lower, but users should remain cautious:

  • Be wary of unsolicited emails, texts, or calls requesting personal or financial information, even if they appear related to BigCommerce or known retailers.
  • Verify any communications by contacting merchants directly using official channels, not links provided in messages.
  • Use phishing-reporting tools available in email clients and browsers to flag suspicious messages.
  • Monitor financial statements and accounts for any unusual activity.

What Does This Incident Mean for BigCommerce and Its Users?

This breach highlights the risks of third-party app integrations in ecommerce platforms, where supply-chain attacks can cascade through trusted software partners. Merchants should carefully review third-party app permissions and monitor for unusual activity on their storefronts.

BigCommerce’s swift action in identifying, notifying, and mitigating the breach is critical, but users should recognize that no platform is invulnerable. Ensuring layered security practices, including app vetting and employee cybersecurity training, becomes increasingly important.

Clear Takeaway: Stay Alert and Vigilant in the Aftermath

Hackers Abuse Third-Party BigCommerce App to Steal Master of Malt Customer  Data
Hackers Abuse Third-Party BigCommerce App to Steal Master of Malt Customer Data

Customers of affected BigCommerce stores need to stay alert for phishing and scam attempts leveraging the leaked personal contact details. Merchants should audit their app ecosystems and keep communication transparent with their customers about security. While payment information remained secure, exposure of names and addresses can still lead to fraud and identity misuse risks. Proactive user caution combined with organizational security vigilance will help mitigate the broader impact of this supply-chain cyberattack.

React to this story

Related Posts